> Source: [sk109319](https://support.checkpoint.com/results/sk/sk109319)

# sk109319 - Automatic document protection upon share in Check Point Capsule Workspace

| Property | Value |
|----------|-------|
| Solution ID | sk109319 |
| Date Created | 2015-12-28 |
| Last Modified | 2017-04-24 |
| Technical Level | General |
| OS | Android, iOS |
| Platform | Mobile Devices |

## Solution

Background
----------

Sharing a document within the Capsule Workspace�s 'Saved Files' is enforced by the sharing policy. If the policy permits only protected document sharing, the user will be blocked in sharing an unprotected document.

The 'Protect on Share' feature provides the administrator with the option to centrally configure the default protection (per Capsule Workspace profile). It allows the user to automatically protect the document upon sharing (using this protection level).

The document protection settings is taken from the template documents on the Gateway and the shared document will have the same protection settings.

In order to configure this, the administrator needs to create a template document per document type (*.docx* , *.pptx* , *.xlsx*) with the required protection level, and store them on the gateway. The administrator needs to assign these templates to the required Mobile Access Blade profile(s).

Step-by-step guide:
-------------------

The following actions should be taken for every profile.

It is possible to use the same files for different profiles, in which case only repeat the GuiDBEdit part.

1. Create 3 protected documents - a "*docx* ", "*xlsl* " and "*pptx*" (You can choose to skip one or two, but then the user will not be able to protect these kinds of documents).

2. Copy the documents to your Mobile Access gateway to the following folder: *$CVPNDIR/htdocs/MobileApp/Login/images*

3. Make sure the files are owned by admin (*chown admin filename* ) and that they have full access permissions (*chmod 777 file name*).

4. Open GuiDbEdit.

5. Navigate to: 'other \> mobile_profiles \> PROFILE NAME \> future_compatibility_fields'

6. Right-click future_compatibility_fields and choose 'add'.

7. In the "Name" field write: "docs_templates_files" (without the quote).

8. In the "Value" field write the names (including extension) of the template files you wish to use, **comma separated with no spaces** . **The names are case sensitive.** For example if the templates are - "*MyDocument.docx* ", "*MySpreadsheet.xlsx* " and "*MyPresentation.ppt* x", the value must be: "*MyDocument.docx,MySpreadsheet.xlsx,MyPresentation.pptx* " (without the quote).  
   Note that in case you make a chage in a template file you should change the name as well (file name itself and the reference from GuiDBEdit) in order to update the app on the chage.

9. Save in GuiDBedit.

10. Open SmartDashboard and install policy.

**Notes:**

* The protection can ONLY be done for Office 2007 documents and above. Older versions and PDFs are currently not supported.
* When the users login again they get the new policy and download the template files from the gateway.
* On the first "Share" attempt, the user will need to login to the Capsule Docs server - this will be done silently if it is "On Premise with SSO", or if they have already logged in in the past and have chosen "remember me", otherwise a login attempt dialog will pop up.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
